# The Patching Model Is Broken: AI Is Widening the Gap Faster Than Defenders Can Close It


## The Threat


The numbers in Rapid7's Q2 2026 threat report are stark enough to demand attention: high and critical vulnerabilities (CVSS 7.0 and above) doubled year over year, from 4,268 in Q2 2025 to 8,539 in Q2 2026. That is not a spike. That is a structural shift — and the engine driving it is artificial intelligence.


Rapid7 frames the moment as "the compression era," and the name earns its keep. The gap between vulnerability disclosure and weaponized exploitation is compressing. Proof-of-concept code surfaces faster. Attacker tooling converts public vulnerability information into working access with less friction than ever before. What used to take a sophisticated team days now takes a capable actor hours. Traditional 30-day patch cycles were already aspirational for most organizations; against this tempo, they are fiction.


The specific mechanism making this worse is what Christiaan Beek, Rapid7's VP of cyber intelligence, calls the vibe coding feedback loop. AI coding assistants are generating new applications at scale — but they are drawing from old templates that carry old flaws. Researchers have already documented entire classes of AI-generated financial applications sharing identical vulnerability patterns. The same AI capability that finds vulnerabilities in existing software is simultaneously generating new software that inherits vulnerabilities from the past. It is a compounding problem with no natural ceiling.


## Severity and Impact


This report describes a systemic trend rather than a single discrete vulnerability, so the traditional CVE table does not apply directly. The critical metrics are below.


| Metric | Q2 2025 | Q2 2026 | Change |

|---|---|---|---|

| High/Critical disclosures (CVSS 7–10) | 4,268 | 8,539 | +100% YoY |

| New exploited vulnerabilities | ~37 | 40 | +8% YoY |

| "Holy Grail" vulns in exploited set | ~16 of 37 | 25 of 40 | +9 pts YoY |

| Holy Grail share of exploited total | ~43% | 62.5% | Significant increase |


"Holy Grail" is Rapid7's term for vulnerabilities requiring neither credentials nor user interaction — the attacker simply points and shoots. These now represent nearly two-thirds of all actively exploited vulnerabilities tracked in the quarter.


## Affected Products


There is no single vendor or product line at the center of this report — the exposure is systemic. Organizations most at risk share a common profile:


  • Enterprises running AI-generated or vibe-coded applications — particularly in fintech, SaaS, and rapid-development environments where AI code assistants are used without formal security review
  • Organizations with complex API and supply chain dependencies — expanded attack surface that defenders cannot fully inventory, let alone patch in cycle
  • Any team relying on CVSS-score-first triage — the volume of high/critical disclosures has made severity-score-driven prioritization functionally unworkable
  • Sectors targeted by CRINK nation-state actors (China, Russia, Iran, North Korea):
  • - Ukraine and NATO-aligned nations (Russian activity)

    - US and allied government/defense targets (Iranian activity)

    - Taiwan-adjacent technology and government (Chinese activity)

    - Cryptocurrency, financial, and monetizable targets broadly (North Korean activity)


    ## Mitigations


    Rapid7's core argument is that patching everything is no longer a viable strategy — defenders need an exposure-first mindset instead. Concretely, that means:


    Reprioritize your triage model

  • Deprioritize CVSS score alone; weight toward exploitability in the wild and exposure context
  • Treat "Holy Grail" characteristics (no auth, no user interaction, network-exploitable) as immediate escalation triggers regardless of CVSS score
  • Subscribe to Rapid7's AttackerKB, CISA's KEV catalog, and similar exploitation-signal feeds and build them into your triage workflow

  • Address the vibe coding attack surface

  • Implement mandatory SAST/DAST gates in CI/CD pipelines before AI-generated code ships
  • Audit any AI-assisted code for known vulnerable patterns, particularly in authentication, input validation, and cryptography
  • Treat AI-generated code as untrusted third-party code until it clears review — not as internal first-party code

  • Shrink your exploitable perimeter

  • Identify and reduce internet-exposed attack surface aggressively; every unauthenticated, network-reachable service is a potential Holy Grail target
  • Apply network segmentation to limit lateral movement from exploited edge devices and APIs
  • Accelerate patching specifically for no-auth, no-interaction vulnerabilities over lower-severity issues requiring user interaction

  • Assume nation-state targeting if relevant

  • Organizations in defense, critical infrastructure, financial services, and government should treat CRINK targeting as active rather than theoretical
  • Apply Zero Trust architecture principles and enforce MFA on all administrative access

  • ## References


  • [Rapid7 "The Compression Era" Q2 2026 Threat Report](https://www.rapid7.com/)
  • [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
  • [Rapid7 AttackerKB](https://attackerkb.com/)
  • [SecurityWeek: Rapid7 Q2 2026 Analysis](https://www.securityweek.com/)

  • ---


    ## HackWire Analysis


    Here is the number that actually matters from this report: 25 of 40 exploited vulnerabilities in Q2 2026 required no authentication and no user interaction. That is 62.5 percent of everything defenders had to respond to in a single quarter — and it is trending up nine points year over year.


    The mainstream framing of AI's security impact focuses on AI-assisted attacks as a future threat. The Rapid7 data suggests we are past that inflection point. AI is already doubling the rate of high/critical vulnerability discovery, and it is doing so continuously, not in waves. The disclosure pipeline is now permanently running faster than most organizations can consume it.


    What makes this structurally dangerous — not just tactically difficult — is the vibe coding loop. Organizations are deploying AI coding tools to accelerate development while simultaneously using AI scanning to find vulnerabilities. The flaw is that the code generation side is drawing from training data that encodes historical vulnerability patterns. Security debt is being written directly into new applications at AI speed, then discovered at AI speed. The net is that defenders are chasing a moving target that is being continuously regenerated.


    The asymmetry Beek describes — attackers need one entry point, defenders need to cover everything — is not new. But the AI amplification of vulnerability discovery against an expanded API and supply chain perimeter makes it qualitatively different. Traditional perimeter assumptions are gone; the exploitable surface now includes every third-party dependency, every AI-generated endpoint, and every vibe-coded internal tool that shipped without a security review.


    Security teams that are still running monthly patch cycles need a different model now, not next quarter. Exposure management — continuous, prioritized by real-world exploitability, not CVSS score — is the replacement. The teams that internalize this shift will be measurably harder to breach than those waiting for the patching model to catch up with a problem it was never designed to handle.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)